Identity and Access Management glossary

Explore the concepts used across Identity and Access Management, Identity Governance, Access Management, privileged access, authorization and identity security.

Definitions are organized to support search and navigation between related concepts.

Search for a term

Browse by letter

Filter by category

Glossary terms

76 terms· Page 1 of 4
  • Provisioning

    Access Request

    An Access Request is a formal request for new, changed, or extended access to a system, entitlement, or role.

  • Provisioning

    Account Correlation

    Account Correlation is the process of linking discovered accounts in target systems to the correct digital identity in the IAM system.

  • Provisioning

    Account Provisioning

    Account Provisioning is the creation and maintenance of system-specific accounts linked to an identity.

  • Provisioning

    Alternative Scenario

    The Alternative Scenario is the second-best onboarding path combining modern authentication with managed account lifecycle in the target application.

  • Provisioning

    API-Based Integration Path

    An API-Based Integration Path is a custom onboarding route that manages the application through its exposed APIs.

  • Provisioning

    Application Onboarding

    Application Onboarding is the structured process of connecting a new application to the IAM control model for authentication, identity lifecycle, and access governance.

  • Provisioning

    Approval Workflow

    An Approval Workflow is the sequence of review and decision steps required before access is provisioned or changed.

  • Provisioning

    Attribute Mapping

    Attribute Mapping is the process of translating identity data from a source model into the attribute structure required by a target system.

  • Provisioning

    Automated Provisioning

    Automated Provisioning is the execution of provisioning tasks through system-driven workflows rather than manual intervention.

  • Provisioning

    Birthright Access

    Birthright Access is the default access automatically granted to an identity based on basic organizational attributes or status.

  • Provisioning

    Centralized Repository Dependency

    Centralized Repository Dependency is the degree to which an application is already linked to the enterprise identity repository used for onboarding acceleration.

  • Provisioning

    CIAM Integration Layer

    The CIAM Integration Layer is the set of connectors and exchanges used to connect customer identity data with surrounding business and marketing systems.

  • Provisioning

    Custom Connector Normalization

    Custom Connector Normalization is the habit of accepting target-specific integration code as a normal end state instead of a constrained exception.

  • Provisioning

    Custom Development Connector

    A Custom Development Connector is an application-specific integration built when standard protocols are not sufficient.

  • Provisioning

    Delta Provisioning

    Delta Provisioning is a provisioning approach that processes only the changes that occurred since the last synchronization cycle.

  • Provisioning

    Deprovisioning

    Deprovisioning is the process of removing, disabling, or revoking accounts and access rights when they are no longer justified.

  • Provisioning

    Directory Synchronization

    Directory Synchronization is the ongoing synchronization of identity objects and attributes between directories or between a directory and other systems.

  • Provisioning

    Dormant Account

    A Dormant Account is an account that still exists but shows no activity for a prolonged period and may no longer be needed.

  • Provisioning

    Email-Driven Access Process

    An Email-Driven Access Process is an access workflow handled mainly through informal email exchanges instead of structured request channels.

  • Provisioning

    Emergency Deprovisioning

    Emergency Deprovisioning is the urgent removal of access outside normal timelines due to security, legal, or operational risk.

  • Provisioning

    Entitlement Provisioning

    Entitlement Provisioning is the assignment and withdrawal of specific access rights, privileges, or functional grants in target systems.

  • Provisioning

    Event-Driven Provisioning

    Event-Driven Provisioning is a provisioning model where lifecycle actions are triggered by discrete events published by one or more upstream systems.

  • Provisioning

    Favorite Scenario

    The Favorite Scenario is the preferred onboarding path in which the application supports modern delegated authentication and minimizes local account persistence.

  • Provisioning

    Forced Local Account Persistence

    Forced Local Account Persistence is the design choice of keeping permanent local user accounts in an application even when a lighter federated model would be possible.